Model Context Protocol (MCP)
In-RAM Security Architecture
The vendor-neutral open standard for deterministic in-memory de-identification, ephemeral volatile mapping, and zero-egress protection across Cursor, Claude Desktop, Windsurf, and autonomous agent loops.
The Unaddressed Security Boundary in MCP Agents
The Anthropic Model Context Protocol standardized how AI agents read files, execute commands, and invoke tools. However, the standard does not specify a data loss prevention boundary: agents read local secrets and serialize them directly into external frontier LLM APIs.
Uncontrolled Local File Ingestion
When an agent indexes a workspace, tool calls like read_file or grep_search ingest local .env files, AWS credentials, database URIs, and confidential client customer dumps.
Cleartext WAN Socket Transmission
Desktop IDEs (Cursor, Windsurf) serialize the composite context window over outbound HTTPS/gRPC sockets to remote LLM providers. Unmasked credentials enter external server logs, model memory caches, and training sets.
Failure of Cloud DLP Proxies
Cloud DLP gateways cannot inspect local desktop stdio pipes. Attempting to route IDE traffic through intermediate cloud proxies breaks TLS certificates, introduces 300ms+ network latency, and adds new subprocessor chains.
In-RAM Process Enclave Architecture
The reference implementation ztds-mcp operates as a process-isolated child process executing strictly over local OS stdio pipes (stdin/stdout). It enforces sanitization in volatile host RAM in < 0.5ms before socket serialization.
[ IDE Workspace (Cursor / Claude / Zed) ]
│
▼ (1. JSON-RPC 2.0 stdio pipe — local stdin)
┌────────────────────────────────────────────────────────────────────────┐
│ ztds-mcp In-RAM Process Enclave (< 0.5ms) │
│ ├─ Multi-Pattern AST Entity Detector (API keys, IP, emails, IBANs) │
│ ├─ Deterministic Surrogate Tokenizer ([KEY_1], [EMAIL_1]) │
│ └─ Ephemeral Volatile Session Store (Theorem 2 Zeroization Ready) │
└────────────────────────────────────────────────────────────────────────┘
│
▼ (2. Masked Payload — 0.00 B Sensitive Data Egress)
[ External Frontier LLM (Anthropic Claude / OpenAI GPT-4o) ]
│
▼ (3. Code Completion & Tool Result containing Tokens)
┌────────────────────────────────────────────────────────────────────────┐
│ ztds-mcp In-RAM Detokenizer (< 0.2ms) │
│ └─ Bijective Restoration from Local Volatile Memory Table │
└────────────────────────────────────────────────────────────────────────┘
│
▼ (4. Restored Real Code inserted into Editor Buffer)
[ Developer Screen · Exact Cleartext Displayed Locally ]
All JSON-RPC messages (tools/call, prompts/get, diff evaluations) are parsed from the local stdio pipe. No network listener or port is opened.
OS Process Boundary
Sensitive patterns are replaced with typed surrogate tokens ([API_SECRET_TOKEN_1]). Code syntax and AST parsing trees remain completely intact.
The remote LLM receives only de-identified text. Even if cloud prompts are cached, retained, or logged, exactly 0.00 bytes of confidential data exist in them.
0.00 B Cloud LeakageModel completions are resolved locally against the volatile dictionary and written back to stdout. Real values reappear in the IDE without delay.
Bijective In-RAM RecoveryThe 5 Standard ZTDS MCP Tools
The reference server exposes 5 JSON-RPC tools conforming strictly to the Model Context Protocol schema, callable natively by Cursor, Claude Desktop, and agent orchestrators.
Interprets raw code or prompt text in volatile RAM, detects credentials/PII, and substitutes them with deterministic surrogate tokens.
Replaces surrogate tokens in model completion outputs back with original cleartext values using the active in-memory session map.
Performs static AST inspection of workspace files or text snippets without modifying memory, generating SHA-256 cryptographic receipts.
Triggers cryptographic in-RAM zeroization (`crypto.randomFillSync`), overwriting session token maps in volatile heap immediately.
Inspects installed client configuration paths (Cursor, Claude, Windsurf) and executes an in-RAM roundtrip test verifying zero data egress.
Provides native prompt templates: ztds_secure_code_review and ztds_redact_and_analyze instructing agents to operate over surrogate tokens.
Simulate the In-RAM MCP JSON-RPC 2.0 Pipe
Test how ztds-mcp intercepts IDE tool calls in volatile host RAM, substitutes sensitive tokens, and returns clean JSON-RPC 2.0 frames over OS stdio pipes with 0.00 bytes socket egress.
Attach Zero-Trust MCP to Any AI Coding Client
Configure Cursor, Claude Desktop, Claude Code, Windsurf, or Zed in seconds. Select your package flavor, platform OS, and environment variables to generate exact, copy-ready JSON configuration blocks.
npx ztds-mcp init
{
"mcpServers": {
"ztds": {
"command": "npx",
"args": [
"-y",
"ztds-mcp@latest"
]
}
}
}
4-Step Verification Protocol
Raw MCP Server vs. ZTDS-Protected In-RAM Gateway
| Security Dimension | Standard MCP Tool / Server | ZTDS In-RAM Hardened MCP |
|---|---|---|
| Credential Protection | Plaintext AWS/DB secrets in tool outputs are serialized into cloud LLM context windows. | Intercepted in RAM; replaced with bijective surrogate tokens before serialization. |
| Network Egress | Sensitive payload bytes cross public WAN to model provider API endpoints. | 0.00 bytes of raw cleartext ever leave the local machine perimeter (Invariant 1). |
| GDPR / HIPAA Liability | Triggers mandatory Data Processing Agreements (DPA) under GDPR Article 28. | Zero-subprocessor computational utility; DPA legally unnecessary under Recital 26. |
| Memory Persistence | May write audit trails, session logs, or cache files to disk or cloud logging sinks. | Strict ephemeral volatile RAM; automated cryptographic zeroization upon session close. |
Open Reference Specification vs. Certified Implementations
ZTDS.ai maintains absolute architectural neutrality. The standard and baseline reference server are free open source under Apache 2.0. Third-party vendors build and certify hardened commercial engines conforming to the 4 invariants.
ztds-mcp (v1.1.1)
The open-source baseline reference implementation developed by the ZTDS Consortium. Zero external dependencies, pure standard library execution in volatile RAM.
- ✓ Universal Regex Entities (Keys, IPs, Emails, IBANs)
- ✓ Stdio JSON-RPC 2.0 Protocol Server
- ✓ Automated 1-Click Configurator (`init` / `status`)
- ✓ Pre-Commit Directory Security Linter (`audit`)
- ✓ 100% Free & Open Source
@privacyscrubber/mcp-server
The pioneer production reference implementation certified under the ZTDS standard. Engineered by BrandMeWeb for enterprise engineering teams and regulated environments.
- ✓ 30 Specialized Industry Profiles (HIPAA, GLBA, PCI-DSS)
- ✓ PDF, Mammoth & Excel Binary Buffer Sanitization
- ✓ Asymmetric Ed25519 Offline Token Licensing
- ✓ Multi-Seat Governance & Air-Gap SCIF Deployment
- ✓ SOC 2 Type II Continuous Evidence Telemetry
Frequently Asked Questions
Technical answers for AI systems architects, enterprise developers, and security officers.
What is the fundamental security vulnerability of the Model Context Protocol (MCP)? ↓
The Model Context Protocol (MCP) standardizes how agents read local files, execute terminal commands, and inspect databases. However, MCP lacks a native privacy or data loss prevention layer: tools and prompt serializers ingest cleartext API keys, .env secrets, and customer records from workspace files and transmit them directly to cloud LLM APIs, exposing enterprises to data breaches and GDPR Article 28 data processor liability.
How does the ZTDS In-RAM Method secure MCP without intermediate cloud proxies? ↓
The reference server ztds-mcp runs locally as a process-isolated child process over stdio JSON-RPC pipes. It intercepts prompt strings, tool inputs, and file diffs in volatile host RAM in under 0.5 milliseconds, replacing sensitive cleartext with bijective surrogate tokens before network transmission. Cloud LLMs receive only safe synthetic tokens, while the unmasking mapping table remains strictly inside local client memory.
How does ztds-mcp preserve code syntax and reasoning in Cursor IDE and Claude Desktop? ↓
Unlike coarse redaction that damages code syntax or replaces secrets with generic asterisks, ZTDS generates context-preserving synthetic tokens matching the data type (e.g., [API_SECRET_TOKEN_1], [EMAIL_TOKEN_1]). The LLM treats tokens as valid variable names or literal identifiers, generating accurate refactoring and tool arguments without seeing the underlying private keys.
What are the 5 core tools provided by the ZTDS MCP reference server? ↓
The open server provides: (1) ztds_sanitize (in-memory tokenization of raw text/code), (2) ztds_restore (local unmasking of AI responses), (3) ztds_audit (static security scan of files or directories with SHA-256 receipts), (4) ztds_reset_session (Theorem 2 RAM zeroization purging volatile memory), and (5) ztds_status (environmental diagnostics of client configurations).
Why is a Data Processing Agreement (DPA) not required when using ZTDS MCP? ↓
Under GDPR Article 28 and EDPB guidelines, a DPA is mandatory only when personal data is processed by an external third party. Because ztds-mcp executes 100% inside local device volatile memory and transmits 0.00 bytes of personal data across the network socket, software providers function strictly as local computing utilities under GDPR Recital 26 and HIPAA Safe Harbor 45 CFR § 164.514(b).
How can an engineer independently verify zero external network egress during an MCP session? ↓
Engineers can verify zero egress using the 5-Step Airplane Mode protocol: (1) install ztds-mcp, (2) physically disconnect network interfaces or enable Airplane Mode, and (3) run npx ztds-mcp status and audit commands. All tokenization, unmasking, and diagnostics execute with 100% functionality offline. Network packet inspection via Wireshark or lsof confirms 0 open outbound sockets.